Skip to content

CS Professional · Internal and Forensic Audit

Internal Controls for CS Professional Internal Audit

Internal control is the set of policies and procedures a company uses to protect assets, keep records accurate, ensure compliance and run operations well. To answer questions, define the control, link it to a COSO component or Companies Act duty, apply it to the facts, and conclude with a clear recommendation.

What this chapter covers

This chapter explains how a company keeps its operations, records and compliance under control. You start with the meaning, objectives and features of internal control. You then study the COSO framework, the types and techniques of controls, and the legal angle: internal financial controls (IFC) under the Companies Act, 2013 and the Guidance Note on auditing them.

The chapter ends with evaluation and reporting. This is where you learn how an internal auditor tests a control, finds a weakness and tells management or the Audit Committee about it.

In Elective 4.2, Internal Audit carries 60 marks and Forensic Audit carries 40. Controls sit under the whole paper. An internal auditor plans work around control risks. A forensic auditor looks at where controls failed or were overridden. If you understand this chapter well, later chapters on audit planning, fraud and investigation become easier. Elective papers are open book, but you still need to know where to look and how to apply the rule to the facts.

Questions in this paper are written and case-based. A typical question gives you a company scenario with a weak or missing control and asks what the problem is, which provision or framework applies, and what you would recommend. This chapter gives you the vocabulary and structure for those answers. It also links the Companies Act, 2013 to practice: section 138 on internal audit, section 177 on the Audit Committee and section 134-linked reporting on IFC. A student who can name the right control type, tie it to a COSO component and cite the right duty usually writes a more complete answer than one who only describes controls in general.

Internal Controls: topics in the order to study them

  1. 1Internal Control: Meaning, Objectives and FeaturesStart here because every later topic uses these basic ideas: what a control is, what it is meant to achieve and what it cannot guarantee.
  2. 2COSO Internal Control FrameworkIt gives the standard structure of components and principles that you will use to classify and evaluate controls.
  3. 3Types and Techniques of Internal ControlsOnce you know the framework, learn the practical tools such as preventive, detective and corrective controls, and how they work in real processes.
  4. 4Internal Financial Controls under Companies Act 2013Now move from concept to law: who must have IFC, who reports on them and how the Audit Committee, auditors and internal auditor fit in.
  5. 5Guidance Note on Audit of Internal Financial ControlsIt shows how the auditor tests and reports on IFC, so read it after you know the legal requirement.
  6. 6Internal Control Evaluation and ReportingFinish with evaluation and reporting, because it uses everything before it: you assess the design and operation of controls, then communicate the gaps.

How to prepare Internal Controls

Treat this chapter as a framework you apply to cases, not a list to memorise. Build it in layers: concept, framework, tools, law, audit procedure, reporting.

  1. Write the meaning, objectives and features of internal control in your own words, and note the limits of any control system.
  2. Learn the COSO components and principles as a checklist. For each one, make a one-line example from a business such as a manufacturing company or an NBFC.
  3. Make a table-style list in your notes of control types and techniques. Against each, write what risk it addresses and one example.
  4. Read the text of sections 138 and 177 of the Companies Act, 2013 carefully. Note who must appoint an internal auditor, the Audit Committee's minimum size and its role in evaluating internal financial controls and risk management systems.
  5. Read the Guidance Note on audit of IFC for structure: scope, planning, testing and reporting. Focus on how you would explain it to a client, not on copying wording.
  6. Practise two or three case questions in the pattern of provision, analysis of facts, conclusion and recommendation. Time each answer to about the marks it carries.
  7. In the last pass, prepare a one-page evaluation and reporting template: control objective, weakness, risk, recommendation, management response.

Common mistakes in Internal Controls

  • Writing generic definitions of internal control without applying them to the facts given.

    Fix: After a short definition, quote the facts from the case, name the failed control and explain its impact before you recommend a fix.

  • Listing COSO components without linking them to the case.

    Fix: Pick only the components that are relevant to the scenario and show how each is weak or strong.

  • Confusing the roles of the Audit Committee, the statutory auditor and the internal auditor.

    Fix: Keep a three-column note: who appoints, what they review and whom they report to. Cite sections 138 and 177 for the internal auditor and the Audit Committee.

  • Stating section details loosely, such as the Audit Committee's composition.

    Fix: Use the exact wording: minimum three directors, independent directors forming a majority, and the proviso on the ability to read and understand financial statements.

  • Claiming a control system can fully prevent fraud or error.

    Fix: Mention inherent limitations such as collusion, management override and human error, and say controls give reasonable assurance.

  • Ending the answer without a recommendation or a reporting step.

    Fix: Always close with a specific recommendation, who should act on it and how the matter should be reported.

Last-day revision: Internal Controls

  • Internal control is a process that gives reasonable, not absolute, assurance about the achievement of objectives.
  • Controls cover operations, reporting and compliance; the safeguarding of assets runs through all three.
  • Know the COSO components and map each control example to one of them.
  • Preventive controls stop errors, detective controls find them, corrective controls fix them.
  • Segregation of duties, authorisation limits and reconciliations are core control techniques.
  • Section 138: prescribed classes of companies must appoint an internal auditor who is a chartered accountant, a cost accountant or another professional decided by the Board.
  • Section 177: the Audit Committee has at least three directors, with independent directors forming a majority.
  • The Audit Committee's terms of reference include evaluation of internal financial controls and risk management systems.
  • Section 177 also covers scrutiny of inter-corporate loans and investments and approval of related party transactions.
  • The Audit Committee can obtain external professional advice and has full access to company records.
  • Section 177(9) and (10): listed and prescribed companies need a vigil mechanism with safeguards against victimisation.
  • In an evaluation report, state the weakness, its risk, your recommendation and management's response.

Internal Controls practice questions

Internal Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Controls: frequently asked questions

What is the difference between internal control and internal audit?

Internal control is the system of policies and procedures that management puts in place. Internal audit is an independent review of how well that system works. The internal auditor tests controls and reports gaps, but does not own the controls.

Who must appoint an internal auditor under the Companies Act, 2013?

Section 138 requires such classes of companies as are prescribed to appoint an internal auditor. The internal auditor must be a chartered accountant, a cost accountant or another professional decided by the Board. Check the prescribed classes in the rules before answering a case.

What does the Audit Committee do about internal financial controls?

Under section 177(4), its terms of reference include the evaluation of internal financial controls and risk management systems. It can also call for the auditors' comments on internal control systems under section 177(5). It reports through the Board, and the Board's report must disclose its composition.

Is this chapter more theory or case-based?

Expect case-based questions. You will get facts about a company and must identify the control issue, apply the framework or provision and recommend action. Theory alone will not earn full marks.

Do I need to memorise section numbers in an open book paper?

Elective papers are open book, so you can refer to the text. Still, learn the key sections like 138 and 177 well enough to find them fast and apply them correctly, since time is limited.